compute
POST /v1/certificates/orders/{orderId}/submit
Buy the certificate. This spends money.
Xác thực
Gửi khóa API dưới dạng mã thông báo bearer. Khóa này phải có quyền billing.payment.manage; khóa không có quyền này sẽ bị từ chối với mã lỗi 403, không phải 404.
Endpoint này không nhận ID tổ chức. Khóa của bạn đã xác định tổ chức mà nó thuộc về và phản hồi được giới hạn trong phạm vi đó.
Dùng thử
Thay thế bất kỳ nội dung nào trong ngoعل (angle brackets) bằng giá trị của riêng bạn và trình giữ chỗ key bằng một key từ trang tổng quan của bạn.
curl -X POST https://api.zinndigital.com/v1/certificates/orders/{orderId}/submit \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "csr_pem": <string> }'Đã đăng nhập? Bảng điều khiển API trong trang quản lý của bạn sẽ tự điền ID tổ chức thực tế và khóa của riêng bạn, sau đó chạy yêu cầu đối với API trực tiếp để bạn có thể xem phản hồi thực tế. Mở điểm cuối này trong bảng điều khiển API
Chi tiết
⛔⛔ **This is the call that charges.** It is a separate endpoint from the one that creates the order precisely so a client cannot buy while a form is half filled in. ⛔⛔ **The CSR is required and is checked three times** — here, in the service and in the driver. That is not belt-and-braces: the authority accepts an order **without** one, charges for it, and issues nothing. Two such orders were created against our own account on 2026-08-29 by a probe reading validation errors, and the giveaway is how unlike a purchase they look — no common name, no issue date (`docs/272` §9). ⭐ A customer-generated CSR is the better path and the one to encourage: the private key then never leaves their machine. Answers `503` when the authority could not be reached — in which case the order is recorded and reconciled rather than lost. Requires `billing.payment.manage`.
Tham số
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
orderId (path) | Uuid | Có | The order's id, as `listCertificateOrders` reports it. Ours (UUIDv7). |
Nội dung yêu cầu
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
csr_pem | string | Có | The certificate signing request, PEM. ⛔ Required. Without it the authority has nothing to sign and the order is billed and permanently unusable. |
Phản hồi
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
id | Uuid | Có | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
product_code | string | Có | The stable machine key (`positive_ssl`). ⛔ Match on this, never on `product_name` — the name is the certificate authority's marketing string and can be corrected without the pro… |
product_name | string | Có | What the customer reads — the authority's own product name (`PositiveSSL`, `S/MIME Personal`, `Unified Communications Certificate (UCC)`). ⛔ Never a translation key: these are t… |
state | string<pending, awaiting_validation, issued, cancelled, failed, expired> | Có | ⛔⛔ **`awaiting_validation` means PAID AND NOT ISSUED.** The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately… |
common_name | string | Có | The primary domain on the certificate. |
domains | string[] | Có | Additional names (SANs). Empty for a single-domain product. |
period_years | integer | Có | — |
price_minor | integer | Có | What the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill. |
currency | string | Có | — |
validation_instructions | string | Có | What the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse… |
certificate_pem | string | Có | The issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its **private key never is**: a customer-generate… |
chain_pem | string | Có | — |
message | string | Có | Why it failed or was cancelled, in a sentence the customer reads. |
ordered_at | string | Có | — |
issued_at | string | Có | — |
expires_at | string | Có | — |
days_until_expiry | integer | Có | Whole days until `expires_at`, negative once it has lapsed. ⛔ `null` and `0` are DIFFERENT answers and a client must not collapse them: `null` means we could not read an expiry… |
renewable | boolean | Có | Whether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from `expires_a… |
free_alternative_exists | boolean | Có | Whether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so **before** asking somebody… |
renewal_of | Uuid | Có | The order this one renews, so a client can show the chain. |
last_reminded_at | string | Có | When the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches **including the ones it… |
Các lỗi điểm cuối này có thể trả về
401 · 403 · 404 · 422 · 429 · 503